• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1509506

Главная Специалистам База уязвимостей Не установлено обновление Note 1509506

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1509506-2) SAP Support Packages (SAPKB64028, SAPKB70024, SAPKB70109, SAPKB70207, SAPKB71012, SAPKB71107, SAPKB72005, SAPKB73002, SAPKB73003)
Описание
Specified ICAs execute certain functions through referencing specific  URLs.  When an attacker tricks an authenticated user#s browser into  making a request containing a certain URL and specific parameters, the  functions are executed in the business communication area with the  rights of the user. If present, the attacker may use a Cross Site  Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
Как исправить
Make sure that Note 1481392 is implemented in your system. Then implement the corrections using the Note Assistant, or import the current Support Package. The corrections create the report ITS_XSRF_PARAM_BC_SRV_COM in your system. Execute this report.



------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component SAP_BASIS SAP Basis compo...|
| Release 640 SAPKB64013 - SAPKB64027 |
| Release 700 Until SAPKB70023 |
| Release 710 Until SAPKB71011 |
| Release 711 Until SAPKB71106 |
| Release 701 Until SAPKB70108 |
| Release 702 Until SAPKB70206 |
| Release 730 Until SAPKB73001 |
| Release 720 Until SAPKB72004 |
------------------------------------------------------------------------

Execute the report ITS_XSRF_PARAM_BC_SRV_COM after you implement this note.
Ссылки